Episode Summary
Executive Summary: The episode contrasts the hidden fragility of security practices with the power of practical AppSec. Jack opens with a story about an unreadable security policy, then Tanya Jenko recounts how app exploitation, breach response, incident handling, and developer resistance shaped her career. The key message: security only works when policies, tools, and teams are visible, usable, and collaborative.
Main Topics: Invisible security policy and compliance theater (Priority: 5/5): Jack describes how a critical company security policy was technically available but buried in SharePoint under a meaningless filename, making it effectively inaccessible to employees despite passing audits. Tanya’s career shift from developer to hacker (Priority: 5/5): Tanya explains how an SQL injection demo exposed insecurity in one of her apps and inspired her move from software development into application security and penetration testing. Exploitation, blind SQL injection, and data exfiltration (Priority: 5/5): A Canadian government breach led Tanya to analyze logs and later learn that the attacker used blind SQL injection to extract data via yes/no queries over holiday periods. Incident response, help desk, and operational mistakes (Priority: 4/5): Tanya’s team dealt with a major outage caused not by malware but by staff streaming the Olympics; another story shows how help desk mishandling destroyed evidence in a child exploitation case. Training, culture, and cross-team collaboration (Priority: 5/5): Tanya emphasizes that security succeeds when help desk and developers are trained to recognize incidents and partner with security rather than treating it as someone else’s problem. Winning over resistant developers (Priority: 4/5): A hostile dev manager initially rejected AppSec testing, but after leadership explained the cost and consequences of breaches, the team embraced scanning and remediation.
Key Arguments: If a policy is important enough for audits, it must be easy for employees to find and understand. Security programs fail when documentation is buried, poorly named, or placed in unusable systems like SharePoint. Developer intuition and security intuition differ; secure code needs collaboration, not confrontation. AppSec and incident response depend on frontline staff knowing when to escalate rather than trying to fix everything themselves. Attacks can be subtle and non-obvious, such as blind SQL injection, which requires security teams to understand the logic behind yes/no responses. Organizations often misdiagnose outages or breaches when they lack logs, training, or inventory of their systems. Transparency about incidents can build trust with engineers and improve remediation rates instead of hiding problems out of shame.
Data Points: NOC technicians unable to find policy: 10 out of 10 - Jack’s first test of whether employees could locate the company security policy within 15 minutes New hires unable to find policy: 9 out of 10 - Second test after four months with a new technician cohort Senior technicians unable to find policy: 4 out of 5 - Retest of previously tested staff four months later Security policy access time: 15 minutes - Time Jack gave NOC staff to find the policy Policy test frequency: Q1 and four months later - Repeated checks used to prove the accessibility problem persisted Breach data value: 48 Canadian dollars - Price attackers listed Tanya’s organization’s data for on the dark web Holiday attack cadence: Every statutory holiday for a year - Attacker repeatedly targeted the government app during times when staff would not be on call Olympics impact: Entire building streaming the same site - Wireshark showed everyone in the office hitting the Olympics stream, causing bandwidth exhaustion Government cost of one major AppSec incident: Over half a million dollars - Used to persuade a resistant development manager to allow security testing Developer teams involved in AppSec rollout: Five teams - Tanya was trying to launch scanning/testing across multiple development teams Training length for help desk: 20 minutes - Annual training Tanya and Eric gave to help desk staff on incident recognition
Pivotal Quotes: "Do you have a security policy? Yes, of course we do. Is it available for all of your employees to find? Yep, it's right there on SharePoint." — Jack: Opening anecdote about compliance versus actual usability "I had no idea how serious this was. I'm sorry. This will never happen again on my watch." — Development manager: After leadership explained the impact and cost of blocking AppSec testing "I'd rather try 20 false alarms than one where you didn't call and we made a mess." — Tanya: Guidance to help desk about escalating possible incidents
Implications: Security teams should prioritize discoverability, logging, training, and collaboration. Hiding policies or dismissing AppSec leads to real risk, while visible processes and cross-functional trust improve resilience and response.
About Darket Diaries
Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.